Use GitHub private vulnerability reporting when available.
If private reporting is unavailable, open a minimal public issue that says a private security report is needed. Do not include exploit details, credentials, customer data, private keys, wallet material, or recovery secrets in a public issue.
Security reports are welcome for checked-in code, workflows, validators, public documentation that creates a concrete unsafe behavior, and repository configuration under this project's control.
General claims about unrelated repositories, private runtime state, or third-party services are outside this repository's authority unless a direct reproducible link is provided.
A valid report should receive:
- acknowledgement;
- reproduction or a clearly recorded blocker;
- severity and blast-radius assessment;
- smallest safe fix;
- verification and public-safe disclosure decision.
No security guarantee is implied by this policy or by a passing repository validator.